Sophos

W32/Rbot-BCC

Aliases
  • Backdoor.Win32.Rbot.akx
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2006 (4.02)
Protection available since 14 December 2005 22:25:37 (GMT)
Detected by All Sophos products

Action

More Information

W32/Rbot-BCC is a worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-BCC runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

The worm attempts to spread by copying itself to remote network shares with weak passwords and by exploiting the following system vulnerabilities: LSASS (MS04-011), RPC-DCOM (MS04-012), WebDav (MS03-007) and UPNP (MS01-059). W32/Rbot-BCC is a worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-BCC runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

The worm attempts to spread by copying itself to remote network shares with weak passwords and by exploiting the following system vulnerabilities: LSASS (MS04-011), RPC-DCOM (MS04-012), WebDav (MS03-007) and UPNP (MS01-059).

When first run W32/Rbot-BCC copies itself to <System>\logonnui.exe.

The following registry entries are created to run logonnui.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Logon User Interface
logonnui.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Logon User Interface
logonnui.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Logon User Interface
logonnui.exe

Registry entries are set as follows:

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer